CGRC · Question #546
What are the nine steps of Risk Assessment Methodology? Response:
The correct answer is A. 1 - System Characterization. The first step in a typical risk assessment methodology, such as those outlined by NIST, is System Characterization. This involves defining the scope, boundaries, and characteristics of the system to be assessed.
Question
What are the nine steps of Risk Assessment Methodology? Response:
Options
- A1 - System Characterization
- B1 - Impact Analysis
- C1 - System Characterization
- D1 - Control Analysis
How the community answered
(31 responses)- A87% (27)
- B3% (1)
- C3% (1)
- D6% (2)
Why each option
The first step in a typical risk assessment methodology, such as those outlined by NIST, is System Characterization. This involves defining the scope, boundaries, and characteristics of the system to be assessed.
In most widely accepted risk assessment methodologies, including NIST SP 800-30, the initial and foundational step is System Characterization. This step involves a thorough understanding and documentation of the system's mission, functions, architecture, data types, and operating environment. Clearly defining these characteristics ensures that the subsequent risk identification and analysis steps are performed within a precise and relevant context, forming the basis for an effective assessment.
Impact Analysis is typically performed after system characterization and threat identification to determine the consequences of adverse events, not as the first step.
Control Analysis involves reviewing existing security controls, which occurs after risks have been identified, not as the initial step in the methodology.
Concept tested: Risk assessment methodology steps
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.